Scheduled Queries reference information

The table below lists the common fields in the Scheduled Queries page in Cortex XSIAM.

Note

Certain fields are exposed and hidden by default. An asterisk (*) is beside every field that is exposed by default.

Scheduled Queries table

FieldDescription
BQL

Whether the query was created by the native search.

Native search has been deprecated, this field allows you to view data for queries performed before deprecation.

ISSUED BYUser who ran or scheduled the query.
MITRE ATT&CK TACTICMITRE ATT&CK tactics tagged in the scheduled query.
MITRE ATT&CK TECHNIQUEMITRE ATT&CK techniques tagged in the scheduled query.
NEXT EXECUTION
  • For queries that are scheduled to run at a specific frequency, this displays the next execution time.

    For queries that were scheduled to run at a specific time and date, this field will show None.

PUBLIC APIWhether the source executing the query was an XQL query API.
QUERY DESCRIPTIONQuery parameters used to run the query.
QUERY IDUnique identifier of the query.
QUERY NAME
  • For saved queries, the Query Name identifies the query specified by the administrator.
  • For scheduled queries, the Query Name identifies the auto-generated name of the parent query. Scheduled queries also display an icon to the left of the name to indicate that the query is recurring.

query-scheduled.png

QUERY SYNTAXThe exact syntax used to write the query.
SCHEDULE TIMEFrequency or time at which the query was scheduled to run.
XQLWhether the query was created by XQL search.